Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Booking and Rental Manager — Vulnerabilities & Security Advisories 17

All 17 CVE vulnerabilities found in Booking and Rental Manager, with AI-generated Chinese analysis, references, and POCs.

This page documents security vulnerabilities associated with the Booking and Rental Manager plugin, categorized under WordPress weaknesses and tagged for easy navigation. It aggregates a comprehensive collection of identified flaws, ranging from critical privilege escalations to cross-site scripting issues, covering advisory data published between 2020 and 2024. By centralizing these records, the resource allows users to track a vendor's security response timeline, understand the technical details of specific weakness classes affecting this software, and look up a product's complete vulnerability history for audit or remediation purposes. The content is structured to provide clarity for security professionals, site administrators, and developers who need to assess the current risk posture of installations using this booking solution. Information includes affected versions, patch availability, and the nature of the exploitability, ensuring that stakeholders have the necessary context to make informed decisions about updating or isolating affected environments. This aggregation serves as a single source of truth for historical security incidents, helping to identify patterns in how vulnerabilities are introduced and resolved over time. Users can filter results by severity, publication date, or specific component to find relevant data quickly. The goal is to enhance transparency and support proactive security management by making past incidents accessible and understandable. This page does not offer commercial advice but focuses strictly on factual security reporting to aid in the maintenance of safe and reliable web applications.

Vendor: magepeopleteam

CVE ID Title CVSS Severity Published
CVE-2026-85303 WordPress Booking and Rental Manager plugin <= 2.7.7 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium 2026-09-03
CVE-2026-81762 WordPress Booking and Rental Manager plugin <= 2.7.6 - Broken Access Control vulnerability CWE-862 6.5 Medium 2026-08-31
CVE-2026-78257 WordPress Booking and Rental Manager plugin <= 2.7.5 - PHP Object Injection vulnerability CWE-502 8.8 High 2026-08-27
CVE-2026-78258 WordPress Booking and Rental Manager plugin <= 2.7.5 - Broken Access Control vulnerability CWE-862 5.3 Medium 2026-08-24
CVE-2026-59532 WordPress Booking and Rental Manager plugin <= 2.7.2 - Price Manipulation vulnerability CWE-1284 7.5 High 2026-07-27
CVE-2026-57404 WordPress Booking and Rental Manager plugin <= 2.6.9 - Broken Access Control vulnerability CWE-862 6.5 Medium 2026-07-13
CVE-2026-57660 WordPress Booking and Rental Manager plugin <= 2.7.1 - Broken Access Control vulnerability CWE-862 5.3 Medium 2026-06-26
CVE-2026-23972 WordPress Booking and Rental Manager plugin <= 2.6.0 - Broken Access Control vulnerability CWE-862 6.5 Medium 2026-03-25
CVE-2025-69328 WordPress Booking and Rental Manager plugin <= 2.5.9 - PHP Object Injection vulnerability CWE-502 8.8 High 2026-02-20
CVE-2025-64266 WordPress Booking and Rental Manager plugin <= 2.5.4 - PHP Object Injection vulnerability CWE-502 8.8 High 2025-12-18
CVE-2025-49904 WordPress Booking and Rental Manager plugin <= 2.5.3 - Cross Site Scripting (XSS) vulnerability CWE-79 7.1 High 2025-11-06
CVE-2025-47585 WordPress Booking and Rental Manager plugin <= 2.3.8 - Broken Access Control vulnerability CWE-862 6.5 Medium 2025-06-02
CVE-2025-39390 WordPress Booking and Rental Manager plugin <= 2.3.6 - Broken Access Control vulnerability CWE-862 5.3 Medium 2025-04-24
CVE-2025-39457 WordPress Booking and Rental Manager plugin <= 2.2.8 - Broken Access Control vulnerability CWE-862 5.3 Medium 2025-04-17
CVE-2025-27011 WordPress Booking and Rental Manager plugin <= 2.2.8 - Local File Inclusion vulnerability CWE-98 7.5 High 2025-04-15
CVE-2025-26921 WordPress Booking and Rental Manager Plugin <= 2.2.6 - PHP Object Injection vulnerability CWE-502 8.8 High 2025-03-15
CVE-2025-22720 WordPress WpRently | WordPress plugin plugin <= 2.2.1 - Broken Access Control vulnerability CWE-862 5.8 Medium 2025-01-31

All 17 known CVE vulnerabilities affecting Booking and Rental Manager with full Chinese analysis, references, and POCs where available.